CVE-2026-0187: Medium severity image-auth-srv.c gsa_sw_pk_hash_compare vulnerability
Published Sep 15, 2026
·Updated
In gsaswpkhashcompare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Affected Software
1 affected component
image-auth-srv.c gsa_sw_pk_hash_compare
Event History
Sep 15, 2026
CVE Published
via MITRE·06:33 PM
Data Sourced
via MITRE·06:33 PM
DescriptionWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
Exploitation is local and requires System execution privileges. No user interaction is needed.
2
What could a successful exploit allow?
The logic error can lead to local escalation of privilege, with impacts to confidentiality, integrity, and availability.